Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3360

Опубликовано: 31 окт. 2022
Источник: nvd
CVSS3: 8.1
EPSS Средний

Описание

The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowledge of the site secrets, allowing them to generate a valid hash via the wp_hash() function.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:*
Версия до 4.1.7.2 (исключая)

EPSS

Процентиль: 94%
0.1516
Средний

8.1 High

CVSS3

Дефекты

CWE-502
CWE-502

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowledge of the site secrets, allowing them to generate a valid hash via the wp_hash() function.

EPSS

Процентиль: 94%
0.1516
Средний

8.1 High

CVSS3

Дефекты

CWE-502
CWE-502